CVE-2022-39216: Combodo iTop's weak password reset token leads to account takeover
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39216?
CVE-2022-39216 is classified as a medium severity vulnerability that may lead to account takeover due to predictable password reset tokens.
How do I fix CVE-2022-39216?
To fix CVE-2022-39216, upgrade to versions 2.7.8 or 3.0.2-1 of Combodo iTop.
What are the affected versions for CVE-2022-39216?
CVE-2022-39216 affects Combodo iTop versions prior to 2.7.8 and between 3.0.0 and 3.0.2-1.
What is the impact of CVE-2022-39216?
The impact of CVE-2022-39216 includes the potential for an attacker to gain unauthorized access to user accounts.
Is there a workaround for CVE-2022-39216?
No specific workaround is recommended for CVE-2022-39216; the only mitigation is to apply the available updates.